Malware

VBS/Agent.NFK malicious file

Malware Removal

The VBS/Agent.NFK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VBS/Agent.NFK virus can do?

  • Detected script timer window indicative of sleep style evasion
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • A scripting utility was executed
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • A wscript.exe process commonly used in script or document file downloaders initiated network activity
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
infinity2016.no-ip.org

How to determine VBS/Agent.NFK?


File Info:

crc32: C7AF94BB
md5: 7a9f7e9b596bba9ceba343e1f4329dec
name: 7A9F7E9B596BBA9CEBA343E1F4329DEC.mlw
sha1: cfc4b2da5657d2e8401b4439bdd07f25e164f94b
sha256: dd41be72a5f9bc3ef1bc6225eb0fb68619218e6b0d36a4e968ad053b2739f225
sha512: 89edb733341763f3971847331f4fad3b556d303fb52ab05f7f8c38d39728d31998a72e96dd4b7b1f3800e69057633ce5e361051b924751b7b1e61404aca8dec9
ssdeep: 12288:eANwRo+mv8QD4+0V16oylfLtyzO0blzm1faiS9ef9oSDbXQddWb12Bb4YKiKPaPf:eAT8QE+kTy58K0Jz2faB9GxDbXh2F4YF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: QTranslate
FileDescription: QTranslate 6.1.0 Installation
FileVersion: 6.1.0
Comments:
CompanyName: QTranslate
Translation: 0x0409 0x04e4

VBS/Agent.NFK also known as:

K7AntiVirusTrojan ( 004ff7bb1 )
LionicTrojan.Win32.Generic.4!c
DrWebWin32.HLLW.Autoruner3.2731
CynetMalicious (score: 100)
CylanceUnsafe
SangforSuspicious.Win32.Save.a
AlibabaRansom:Win32/Blocker.3f926a58
K7GWTrojan ( 004ff7bb1 )
Cybereasonmalicious.b596bb
SymantecTrojan.Gen.NPE.2
ESET-NOD32VBS/Agent.NFK
APEXMalicious
AvastVBS:Agent-BRE [Trj]
BitDefenderGen:Heur.SMHeist.3
NANO-AntivirusTrojan.Text.VB.epgwph
MicroWorld-eScanGen:Heur.SMHeist.3
TencentWin32.Trojan.Blocker.Ajvz
Ad-AwareGen:Heur.SMHeist.3
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionVBS/Autorun.worm.aako
FireEyeGeneric.mg.7a9f7e9b596bba9c
EmsisoftGen:Heur.SMHeist.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.fyk
eGambitUnsafe.AI_Score_99%
ArcabitTrojan.SMHeist.3
ZoneAlarmTrojan-Ransom.Win32.Blocker.jusp
GDataGen:Heur.SMHeist.3
AhnLab-V3Trojan/Win32.Blocker.C1699991
McAfeeArtemis!7A9F7E9B596B
MAXmalware (ai score=80)
VBA32TrojanRansom.Blocker
PandaTrj/CI.A
YandexTrojan.Blocker!4IaH4c5CO1E
IkarusTrojan.Win32.Meredrop
MaxSecureTrojan-Ransom.Win32.Crypmod.zfq
FortinetVBS/Agent.NFK!worm
AVGVBS:Agent-BRE [Trj]
Paloaltogeneric.ml

How to remove VBS/Agent.NFK?

VBS/Agent.NFK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment